Microsoft Is Retiring SMS Authentication: What the Entra ID Passkey Mandate Means for Your Organization
On July 13, Microsoft announced one of the most consequential changes to enterprise authentication in years. Beginning September 1, 2026, passkeys will become the default authentication experience in Microsoft Entra ID. Then, on February 1, 2027, Microsoft will retire its own SMS and voice authentication delivery entirely. If your organization has users who verify their sign-ins with a text message or a phone call today, this change reaches every one of them, and the window to plan is measured in weeks, not quarters.
This post walks through exactly what Microsoft announced, why the company is making the change, who is affected, and the three realistic paths forward. Our goal is to give you a clear picture you can bring to your next IT leadership meeting, whether or not you ever talk to us.
The timeline, in plain English
Three dates matter, and one of them arrives before the others get any attention.
On September 1, 2026, Microsoft begins rolling out passkeys as the default authentication experience in Entra ID. As the rollout reaches each tenant, users who are currently enabled for SMS or voice authentication will automatically be enabled for passkeys. The next time those users perform multifactor authentication, they will be prompted to register a passkey. Users who already sign in with phishing-resistant methods such as passkeys, Windows Hello for Business, FIDO2 security keys, or smart cards are not affected and can continue using those methods.
On September 18, 2026, Microsoft plans to publish details about supported third-party telecom providers, along with deployment guidance and commercial terms, for organizations that need to keep SMS or voice for regulatory or business reasons. Starting October 30, 2026, administrators can select and configure one of those providers through the Microsoft Security Store, which is Microsoft’s partner marketplace. You contract with the carrier directly and pay the associated charges.
On February 1, 2027, Microsoft retires its native SMS and voice delivery. After that date, a user whose only available MFA method is SMS or voice will be required to register a passkey during sign-in before they can continue into their account. Microsoft describes this prompt as blocking. In other words, the deadline is not soft. A user who has not transitioned by then does not get a grace period; they get a registration wall.
One scoping note worth flagging: Microsoft has stated that these dates apply to Entra ID in the public cloud only. Sovereign and government cloud environments will follow on a separate timeline, with guidance to be announced. If you operate in a government cloud, you have more runway, but the direction of travel is the same.
Why Microsoft is doing this
The short answer is that SMS and voice authentication have not kept pace with the threat environment. Both methods rely on shared secrets and channels that attackers have learned to intercept, phish, or socially engineer. SIM swapping is a repeatable criminal service. MFA fatigue and bypass techniques are commodity tradecraft. And artificial intelligence has sharply raised attacker productivity: Microsoft Threat Intelligence reports that AI-enabled phishing campaigns are achieving click-through rates as high as 54 percent, compared with roughly 12 percent for traditional campaigns.
Passkeys address this by removing the shared secret entirely. A passkey uses public-key cryptography. The private key never leaves the user’s device or credential manager, nothing phishable is typed or transmitted, and the credential is bound to the legitimate site, so a lookalike phishing page has nothing to steal. For users, the day-to-day experience is usually faster than a text message: a fingerprint, a face scan, or a PIN, and they are in.
It is fair to note that Microsoft’s motives are not purely altruistic; retiring its telecom delivery also retires a cost center. But on the security merits, the industry consensus is not in serious dispute. SMS was always the weakest widely deployed second factor, and phishing-resistant authentication is where every major standard, from CISA guidance to the FIDO Alliance, has been pointing for years.
Who is affected, and how much
The practical impact depends entirely on how many of your users still rely on SMS or voice. In most organizations, these users cluster in predictable places: frontline and seasonal staff, adjunct faculty and student workers in higher education, contractors and affiliates, and long-tenured employees who set up their MFA years ago and never revisited it. In a university environment, the population can be large and it turns over every semester, which makes the timing of this transition, landing squarely in an academic year, genuinely awkward.
The good news is that the change costs nothing in licensing terms. Moving users to passkeys carries no additional Microsoft fee, and Entra ID supports both major passkey types. Synced passkeys are stored in a credential manager such as iCloud Keychain or Google Password Manager and follow the user across devices. Device-bound passkeys live on a specific device or security key, including Microsoft Authenticator, passkeys on Windows through Windows Hello, and hardware FIDO2 keys, and offer a higher assurance profile that some regulated environments prefer.
Your three paths forward
The first path, and the right one for most organizations, is to move affected users to passkeys before the deadlines do it for you. Microsoft’s automatic prompts will technically handle registration on their own, but an unmanaged rollout means your help desk absorbs the confusion in real time, one surprised user at a time. A managed rollout, meaning you inventory affected users, choose which passkey types to allow, pilot with a friendly group, and communicate before the prompts appear, turns a support incident into a routine project. We will publish a step-by-step migration checklist in the coming weeks.
The second path is to keep SMS or voice through a third-party telecom provider. This is the right answer only for organizations with a genuine regulatory or operational requirement, because it now comes with procurement work, a direct carrier contract, and ongoing per-message costs that used to be absorbed by Microsoft. If you are considering this route, treat the September 18 provider announcement as your starting gun and budget time for contracting well before February.
The third path is the honest one for most large environments: a mix. Move the majority to passkeys, retain a compliant SMS channel through a partner for the narrow population that truly needs it, and set a sunset date for that exception so it does not become permanent. The organizations that struggle with transitions like this are rarely the ones that chose the wrong path; they are the ones that never explicitly chose at all.
What to do this month
Before anything else, get the numbers. Pull the authentication methods report in Entra and count how many users are enabled for SMS or voice, and how many have no phishing-resistant method registered. That single figure tells you whether this is a memo or a project. From there, decide your passkey posture, meaning which types you will allow and for whom, brief your help desk on what the registration prompt will look like, and draft the user communication now so it is ready when the rollout reaches your tenant. September 1 is closer than it feels.
Authentication transitions like this one rarely happen in isolation. Most of the organizations we work with are managing them alongside multiple directories, hybrid Active Directory environments, and applications that authenticate in different ways, which is exactly the complexity the OptimalCloud and the Virtual Identity Server were built to simplify. If you would like a second set of eyes on your transition plan, or you are rethinking your broader authentication strategy while you are at it, we are happy to help. Multifactor authentication has been included in every OptimalCloud base package since the beginning, because we have never believed proper security should cost extra.
Contact us for more information.
Frequently Asked Questions
When do passkeys become the default in Microsoft Entra ID?
Microsoft begins rolling out passkeys as the default authentication experience on September 1, 2026. The rollout reaches tenants progressively, and users enabled for SMS or voice authentication will be prompted to register a passkey the next time they perform multifactor authentication.
When does SMS authentication stop working in Entra ID?
Microsoft retires its native SMS and voice authentication delivery on February 1, 2027. After that date, users whose only MFA method is SMS or voice must register a passkey before they can continue signing in, and organizations that need to keep SMS must use a third-party telecom provider contracted through the Microsoft Security Store.
What is a passkey?
A passkey is a phishing-resistant credential based on public-key cryptography. The private key stays on the user’s device or in their credential manager, and the user unlocks it with a biometric or PIN. Because no shared secret is typed or transmitted, passkeys cannot be phished or intercepted the way SMS codes can.
Can my organization keep using SMS after February 2027?
Yes, but only through a supported third-party telecom provider selected and configured through the Microsoft Security Store, with contracting and charges handled directly with the carrier. Microsoft plans to publish supported providers and pricing details on September 18, 2026, and configuration opens on October 30, 2026.
Does this change affect government or sovereign cloud tenants?
Not on this timeline. Microsoft has stated the announced dates apply to Entra ID in the public cloud only, with separate timelines and guidance for other cloud environments to be announced in advance.
Does moving to passkeys cost anything?
There is no additional Microsoft licensing fee to move users from SMS or voice to passkeys. The costs to plan for are operational: project time, help desk preparation, user communication, and hardware security keys if your organization chooses device-bound passkeys for certain roles.


